Cyble Recognized in the 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies — and What Cyble Feels It Means for the Next Era of Threat Intel
Cyble has been recognized as a Challenger in the 2026 Gartner® Magic Quadrant™ for CTI. Here’s what it means for the future of threat intelligence.
La Cina ha già lanciato i primi satelliti per elaborare dati in orbita. Gli Stati Uniti, tra Pentagono, Google e SpaceX, stanno facendo lo stesso. Sta nascendo una nuova infrastruttura digitale globale, che però non appartiene a nessuno Stato e che nessuna legge regola ancora
Microsoft fixes BitLocker recovery bug on Windows Server 2025
Microsoft has resolved a known issue causing some Windows Server 2025 devices to boot into BitLocker recovery after installing the April 2026 security update.
AI nella PA: la formazione di massa alla prova della sicurezza dei dati e della conformità normativa
La diffusione di Microsoft 365 Copilot nella Pubblica Amministrazione accompagna un ampio sforzo formativo, da analizzare dal duplice punto di vista della sicurezza dei dati e della conformità normativa. Ecco quali sono le problematiche e le possibili soluzioni
L’importanza della discovery e dell’osservabilità nell’era agentica
La maggior parte dei programmi di sicurezza dà per scontato che applicazioni e agenti AI siano autorizzati dall'IT e monitorati. Ecco cosa offrono gli agenti OpenClaw ai CISO e responsabili della cyber security interessati alla visibilità unificata e a garantire che l'osservabilità degli agenti non sia isolata
L’adozione dell’AI tra Mythos e Fable 5: le nuove sfide alla sicurezza nazionale
Project Glasswing e i modelli Mythos di Anthropic aprono una nuova fase della cyber sicurezza. La capacità di individuare migliaia di vulnerabilità in tempi record promette vantaggi difensivi senza precedenti, ma solleva interrogativi su sovranità digitale, sicurezza nazionale e dipendenza tecnologica europea
Sniper’s Nest: From Brand Impersonation to Browser Hijacking and CPA Fraud
This blog provides a deep-dive into SniperDz, a centralised PhaaS platform with more than 80 ready-made phishing templates impersonating over 30 global brands, and uncovers the hidden infrastructure behind this sophisticated and highly-organized fraud ecosystem.
Nottingham University data breach affects over 450,000 students
The University of Nottingham confirmed on Wednesday that a hacking group gained access to its student records system in a breach affecting both current students and alums.
Max severity Ivanti Sentry vulnerability now exploited in attacks
Attackers are now targeting a recently patched maximum-severity flaw in Ivanti Sentry, enabling them to execute code with root privileges on Internet-exposed secure mobile gateways.
University of Nottingham - 454,635 breached accounts
In June 2026, the University of Nottingham was the target of a cyber attack, later linked to a ShinyHunters "pay or leak" extortion campaign. Tens of gigabytes of data were subsequently published online and included 455k unique email addresses along with extensive personal information including names, addresses, phone numbers, ethnicities, disabilities, passport numbers and information relating to academic enrolments and fee payments. In a post about the incident, the university advised that the breach affected both "current students, and alumni".
Path traversal flaw in AI dev platform Langflow exploited in attacks
Attackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in the AI development platform Langflow, to write arbitrary files on exposed servers.
The ‘Miasma’ worm source code briefly leaked on GitHub
The Miasma credential-stealing attack framework, which has recently targeted open-source ecosystems through supply-chain attacks, was briefly open-sourced on GitHub.
GitHub announces npm security changes to tackle supply-chain attacks
GitHub has announced that npm v12, expected next month, will introduce several security-focused changes aimed at blocking supply-chain attacks abusing behaviors triggered by the 'npm install' command.
Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks
Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations.
Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws
Today is Microsoft's June 2026 Patch Tuesday, with security updates for 200 flaws, including five publicly disclosed zero-day vulnerabilities and one actively exploited in attacks.
Microsoft June 2026 Patch Tuesday fixes 5 zero-days, 200 flaws
Today is Microsoft's June 2026 Patch Tuesday, with security updates for 200 flaws, including four publicly disclosed zero-day vulnerabilities and one actively exploited in attacks.
Aggiornamenti Microsoft giugno 2026: tre zero-day e il ritorno di Nightmare Eclipse
Il Patch Tuesday di giugno 2026 è il più grande della storia di Microsoft: 206 CVE corrette, di cui 33 critiche e una in Exchange Server già sfruttata in rete. Sullo sfondo, il ricercatore Nightmare Eclipse che annuncia un nuovo attacco per il 14 giugno sfruttando due zero-day, YellowKey e GreenPlasma, delle tre corrette questo mese
China-linked JDY botnet expands targeting of U.S. military networks
The JDY botnet, a malware network previously associated with Chinese threat actors like Volt Typhoon, has significantly expanded its targeting scope and reconnaissance efforts.
The 5 Best Practices for Secure Identity Verification
Attackers are increasingly bypassing weak authentication through phishing, MFA fatigue, and service desk social engineering. Specops Software breaks down five best practices for stronger identity verification and access security.
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid…
Claude Fable 5 e Mythos 5: i nuovi rischi cyber dell’AI avanzata
Le due varianti differiscono solo per il perimetro dei controlli: l’apparato di safeguard è l’unico confine tra le capacità ordinarie e quelle offensive. Ecco il modello di minaccia associato alle capacità di agentic hacking di Claude Fable 5 e Mythos 5, le evidenze e i limiti in materia di resistenza agli universal jailbreak